Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in libinput
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in libinput
ID: USN-5382-1
Distribution: Ubuntu
Plattformen: Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 21.10
Datum: Do, 21. April 2022, 07:18
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1215
Applikationen: libinput

Originalnachricht

--===============3892081884550821010==
Content-Type: multipart/signed; boundary="=-=-=";
micalg=pgp-sha512; protocol="application/pgp-signature"

--=-=-=
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-5382-1
April 20, 2022

libinput vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

libinput could be made to crash or expose sensitive information.

Software Description:
- libinput: Input device management and event handling library

Details:

Albin Eldstål-Ahrens and Lukas Lamster discovered libinput did not properly
handle input devices with specially crafted names. A local attacker with
physical access could use this to cause libinput to crash or expose
sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.10:
libinput10 1.18.1-1ubuntu0.1

Ubuntu 20.04 LTS:
libinput10 1.15.5-1ubuntu0.3

Ubuntu 18.04 LTS:
libinput10 1.10.4-1ubuntu0.18.04.3

After a standard system update you need to log out of all desktop sessions
and then log back in to make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5382-1
CVE-2022-1215

Package Information:
https://launchpad.net/ubuntu/+source/libinput/1.18.1-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libinput/1.15.5-1ubuntu0.3
https://launchpad.net/ubuntu/+source/libinput/1.10.4-1ubuntu0.18.04.3

--=-=-
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQFOBAEBCgA4FiEEiOlTC8vdwgBRe16w9JjS2d59rZwFAmJgmLMaHGFsZXgubXVy
cmF5QGNhbm9uaWNhbC5jb20ACgkQ9JjS2d59rZx4sAgAkqdKOjbeUMmCf0pT6XWU
5pI85X0NsAHL6FfMTnSrguxpUAxL58K0jRfBqE1u0cmCmADCFmhH+Bwkgs6s2Q4p
qE7NN19stvmvu3ybJOhAhbHI15YBaX4Hzh9K5D0plkmFSQumO89TGcxHgAsCRSxP
o2cFOiNaxT2YSOW8qu37x7JedaYQcuWnRDC6Psx6TPIFqS26OzOYUdK9+KmyJSSX
Fc1uVm7MqmL+3iBS7lirVV+F4doCcUm9KcPWHuS1I6DcV/K8Sk8iZV0DJ1QhL8Hi
nApqroN1XO2hEcGsWvZ4bAiCqEqvm4d9tbu7Tc5u5OoeK7U4eMdwcTrE9fK3h48+
Aw==
=4yEz
-----END PGP SIGNATURE-----
--=-=-=--


--===============3892081884550821010==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

Cg==

--===============3892081884550821010==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung